Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 3Objective 2

Application Protocol Analytics GCDA Practice Questions (Page 9)

Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 41–45

  1. 41application · medium

    A security analyst is reviewing network traffic and notices that an internal client is sending HTTP requests to a web server with the following pattern: the URI contains encoded characters that decode to SQL syntax, and the requests are repeated with slight variations. The analyst suspects a SQL injection attempt. Which additional observation would most strongly support this hypothesis?

    Select an answer first
  2. 42foundation · easy

    A network analyst observes traffic on TCP port 445 between two internal hosts. Which application protocol is most likely being used?

    Select an answer first
  3. 43application · medium

    During a hunt, you observe a workstation making repeated connections to an external IP on TCP port 443. The TLS certificate presented is self-signed and the SNI field contains a random-looking alphanumeric string. The user denies visiting any unusual websites. Which additional evidence would most strongly indicate that this is not normal HTTPS web browsing?

    Select an answer first
  4. 44expert · hard

    A detection team is investigating a potential data exfiltration via HTTPS. They have network visibility but no access to the client or server. The traffic is to a well-known cloud storage service, and the volume is consistent with normal business use. The team needs to determine if the traffic is malicious without disrupting business operations. Which approach best balances the need for detection with the constraint of not decrypting traffic?

    Select an answer first
  5. 45application · medium

    You are analyzing TLS traffic and notice that a client is using a very old TLS version (TLS 1.0) to connect to an internal server. The server is a modern application server. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCDA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.